EN RU
List your company
Payments

PCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is the security standard that any organisation storing, processing or transmitting cardholder…

By Daniel Cohen · CMO Updated 6 September 2026
In brief

PCI DSS (Payment Card Industry Data Security Standard) is the security standard that any organisation storing, processing or transmitting cardholder data must meet. It is maintained by the card networks and enforced through acquirers and processors, with requirements covering network security, encryption of cardholder data in transit and at rest, access control, vulnerability management, logging and monitoring, and regular testing.

Definition

PCI DSS (Payment Card Industry Data Security Standard) is the security standard that any organisation storing, processing or transmitting cardholder data must meet. It is maintained by the card networks and enforced through acquirers and processors, with requirements covering network security, encryption of cardholder data in transit and at rest, access control, vulnerability management, logging and monitoring, and regular testing.

Compliance is validated annually, with the depth of validation (a self-assessment questionnaire versus a full external audit) scaling to transaction volume and how the merchant handles card data.

The practical way most merchants reduce their PCI burden is to avoid touching raw card data at all: using a hosted payment page, an iframe, or tokenisation so the card details go straight to a PCI-compliant provider and the merchant only ever handles a token. This shrinks the scope of what has to be secured and audited.

Compare iGaming payment providers

In context

For licensed iGaming operators, PCI DSS is a baseline obligation that sits alongside gambling-specific regulation. Operators almost always keep card data out of their own systems by using a PCI-compliant PSP and tokenisation, so their own scope is limited, but they remain responsible for the parts they control: the security of the pages that load the payment form, protection against injection and skimming attacks on the checkout, secure handling of any stored tokens, access controls, and vendor due diligence on every provider in the payment path.

A card-data breach would bring network penalties, acquirer action, regulatory scrutiny and serious reputational damage on top of the direct incident cost.

For affiliates, PCI DSS is not something they handle directly (they should never be collecting card data), but it is part of assessing whether an operator is a safe recommendation. A legitimate licensed operator will process cards through recognised PCI-compliant providers, show a hosted or tokenised payment flow, and run checkout over properly configured TLS.

Signs to the contrary — a site asking for full card details in a plain form on its own domain, insecure connections, or card data reused across unrelated sites — indicate poor security practice and are a reason not to promote the brand. Affiliates covering payment security for readers can accurately say that reputable operators do not store card numbers themselves and that entering card details should always happen on a secure, provider-backed page.

Worked example

An operator processes all card payments through a PCI-compliant PSP using a hosted payment page, so raw card numbers never reach its servers and its PCI scope is minimal. Its security team still monitors the checkout for script-injection and keeps vendor attestations current.

An affiliate review notes the operator uses a recognised payment provider and a secure hosted checkout as a trust signal.

Related terms

Frequently asked questions

How does PCI DSS work in practice?+
For licensed iGaming operators, PCI DSS is a baseline obligation that sits alongside gambling-specific regulation.
Can you give an example of PCI DSS?+
An operator processes all card payments through a PCI-compliant PSP using a hosted payment page, so raw card numbers never reach its servers and its PCI scope is minimal. Its security team still monitors the checkout for script-injection and keeps vendor attestations current.
What terms are closely related to PCI DSS?+
The closest related terms are TLS/SSL certificate, High-risk merchant, 3-D Secure (3DS), 2FA (two-factor authentication). Each is linked in the related-terms block below.
← Previous PBN (private blog network) Next → PDL offers

Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.

← Back to glossary